The risk intelligence cycle is the method ISO/TS 31050 uses to turn scattered external signals into decisions leadership can act on. It runs continuously: gather signals, make sense of them, assess what they mean, communicate the finding, and feed it back into monitoring. It keeps an emerging risk under active management instead of sitting undetected until it becomes a crisis.
Traditional risk monitoring checks known risks on a schedule. The risk intelligence cycle in ISO/TS 31050 does something more demanding, because an emerging risk gives no reliable schedule and no clean data to check against. The cycle is a continuous loop that treats faint, external signals as the raw material of risk management and converts them, step by step, into something a decision maker can use.
It begins with gathering. The organisation scans beyond its own walls, across markets, technology, regulation, geopolitics and the wider environment, for signals that something is shifting. These signals are then interpreted, because a single data point rarely means much on its own, and the skill lies in connecting weak signals into a pattern that suggests a genuine emerging risk rather than noise.
From there the cycle moves to assessment and communication. The interpreted signal is judged for its uncertainty, its velocity and its potential impact on the organisation, using emerging risk criteria rather than a standard matrix. The result is then communicated to the people who can act, framed honestly so that a board hears a credible read on an uncertain risk instead of false precision. Finally the finding feeds back into monitoring, sharpening what the organisation watches for next.
Run well, the cycle closes the gap that stalls most emerging risk programmes, where a signal is noticed but nothing converts it into a resourced response. Participants on the ISO/TS 31050 Emerging Risks Manager course practise each stage on a working example, so the cycle becomes a repeatable capability rather than a diagram, and it connects directly to the wider way ISO/TS 31050 extends the ISO 31000 process.
“A signal nobody acts on is worse than no signal at all. The intelligence cycle exists so a weak signal actually reaches the person who can act on it.”
Browse all Governance, risk & compliance training courses
The PECB ISO/TS 31050 Emerging Risks Manager certification proves you can identify, assess and treat emerging risks using ISO/TS 31050 inside an ISO 31000 process. It qualifies you to run an emerging risk programme in a risk, resilience or governance role, and to give a board a credible read on exposure that cannot yet be quantified.
byHenri HAENNI
An emerging risk is a threat that is developing but not yet well understood, with no reliable history to estimate how likely it is or how hard it will hit. A conventional risk is already known and can be measured against past data. The difference matters because standard risk tools tend to overlook emerging risks until they are already causing damage.
byAlexis HIRSCHHORN
ISO 31000 sets the general principles and process for managing any risk, while ISO/TS 31050 is a technical specification that extends that process to emerging risks: threats that surface as weak, uncertain signals with no historical data. You apply 31050 inside the 31000 framework, not as a replacement for it.
byHenri HAENNI
The PECB ISO/TS 31050 Emerging Risks Manager certification proves you can identify, assess and treat emerging risks using ISO/TS 31050 inside an ISO 31000 process. It qualifies you to run an emerging risk programme in a risk, resilience or governance role, and to give a board a credible read on exposure that cannot yet be quantified.
Abilene Academy delivers the ISO/TS 31050 course in three formats: in person in Morges, virtual live with an instructor, and self-study at your own pace. All three cover the same two-day programme and lead to the same PECB exam and certification.
The ISO/TS 31050 Emerging Risks Manager training runs over two days. The certification exam is a separate two-hour session, and at Abilene Academy the same two-day format is available onsite in Morges, as virtual live training, or as self-study.
An emerging risk is a threat that is developing but not yet well understood, with no reliable history to estimate how likely it is or how hard it will hit. A conventional risk is already known and can be measured against past data. The difference matters because standard risk tools tend to overlook emerging risks until they are already causing damage.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.